<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Cluster issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037897#M145884</link>
    <description>&lt;P&gt;I have two ASA5545 and two catalyst4507 switch. Switches are in vss mode. I have to cluster both &amp;nbsp;the ASA through switch.&lt;/P&gt;
&lt;P&gt;Configuration is as below:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-2# sh run cluster&lt;BR /&gt;cluster group ASA-CLUSTER&lt;BR /&gt; local-unit ASA-2&lt;BR /&gt; cluster-interface Port-channel10 ip 192.168.21.3 255.255.255.248&lt;BR /&gt; priority 2&lt;BR /&gt; health-check holdtime 3&lt;BR /&gt; health-check data-interface auto-rejoin 3 5 2&lt;BR /&gt; health-check cluster-interface auto-rejoin unlimited 5 1&lt;BR /&gt; clacp system-mac auto system-priority 1&lt;/P&gt;
&lt;P&gt;ASA-1# sh run cluster&lt;BR /&gt;cluster group ASA-CLUSTER&lt;BR /&gt; local-unit ASA-1&lt;BR /&gt; cluster-interface Port-channel10 ip 192.168.21.2 255.255.255.248&lt;BR /&gt; priority 1&lt;BR /&gt; console-replicate&lt;BR /&gt; health-check holdtime 3&lt;BR /&gt; health-check data-interface auto-rejoin 3 5 2&lt;BR /&gt; health-check cluster-interface auto-rejoin unlimited 5 1&lt;BR /&gt; clacp system-mac auto system-priority 1&lt;/P&gt;
&lt;P&gt;-------------------------------------------&lt;BR /&gt;ASA-2# sh run inter gi0/7&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt; channel-group 10 mode on&lt;BR /&gt;ASA-2#&lt;/P&gt;
&lt;P&gt;-----------------------------------------&lt;BR /&gt;ASA-1# sh run inter gi0/7&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt; channel-group 10 mode on&lt;BR /&gt;ASA-1#&lt;/P&gt;
&lt;P&gt;----------------------------------------------&lt;BR /&gt;on switch&lt;/P&gt;
&lt;P&gt;SW- inter gi1/1/4&lt;BR /&gt; - swi mode acc&lt;BR /&gt; - swi acc vlan 23&lt;BR /&gt; - channel-group 10 mode on&lt;/P&gt;
&lt;P&gt;--inter gi2/1/4&lt;BR /&gt; - swi mode acc&lt;BR /&gt; - swi acc vlan 23&lt;BR /&gt; - channel-group 10 mode on&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;now only one ASA is reachable from switch. means when ASA-1 (IP .2) is reachable from switch but not ASA-2 (IP- .3).&lt;/P&gt;
&lt;P&gt;When I removing cable from ASA-1 then ASA-2 is reachable. So how they will sync.&lt;/P&gt;
&lt;P&gt;when enabling cluster both ASA &amp;nbsp;becomes MASTER.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any solution ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 09:02:37 GMT</pubDate>
    <dc:creator>veevekraj</dc:creator>
    <dc:date>2019-03-12T09:02:37Z</dc:date>
    <item>
      <title>ASA Cluster issue</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037897#M145884</link>
      <description>&lt;P&gt;I have two ASA5545 and two catalyst4507 switch. Switches are in vss mode. I have to cluster both &amp;nbsp;the ASA through switch.&lt;/P&gt;
&lt;P&gt;Configuration is as below:-&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ASA-2# sh run cluster&lt;BR /&gt;cluster group ASA-CLUSTER&lt;BR /&gt; local-unit ASA-2&lt;BR /&gt; cluster-interface Port-channel10 ip 192.168.21.3 255.255.255.248&lt;BR /&gt; priority 2&lt;BR /&gt; health-check holdtime 3&lt;BR /&gt; health-check data-interface auto-rejoin 3 5 2&lt;BR /&gt; health-check cluster-interface auto-rejoin unlimited 5 1&lt;BR /&gt; clacp system-mac auto system-priority 1&lt;/P&gt;
&lt;P&gt;ASA-1# sh run cluster&lt;BR /&gt;cluster group ASA-CLUSTER&lt;BR /&gt; local-unit ASA-1&lt;BR /&gt; cluster-interface Port-channel10 ip 192.168.21.2 255.255.255.248&lt;BR /&gt; priority 1&lt;BR /&gt; console-replicate&lt;BR /&gt; health-check holdtime 3&lt;BR /&gt; health-check data-interface auto-rejoin 3 5 2&lt;BR /&gt; health-check cluster-interface auto-rejoin unlimited 5 1&lt;BR /&gt; clacp system-mac auto system-priority 1&lt;/P&gt;
&lt;P&gt;-------------------------------------------&lt;BR /&gt;ASA-2# sh run inter gi0/7&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt; channel-group 10 mode on&lt;BR /&gt;ASA-2#&lt;/P&gt;
&lt;P&gt;-----------------------------------------&lt;BR /&gt;ASA-1# sh run inter gi0/7&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet0/7&lt;BR /&gt; channel-group 10 mode on&lt;BR /&gt;ASA-1#&lt;/P&gt;
&lt;P&gt;----------------------------------------------&lt;BR /&gt;on switch&lt;/P&gt;
&lt;P&gt;SW- inter gi1/1/4&lt;BR /&gt; - swi mode acc&lt;BR /&gt; - swi acc vlan 23&lt;BR /&gt; - channel-group 10 mode on&lt;/P&gt;
&lt;P&gt;--inter gi2/1/4&lt;BR /&gt; - swi mode acc&lt;BR /&gt; - swi acc vlan 23&lt;BR /&gt; - channel-group 10 mode on&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;now only one ASA is reachable from switch. means when ASA-1 (IP .2) is reachable from switch but not ASA-2 (IP- .3).&lt;/P&gt;
&lt;P&gt;When I removing cable from ASA-1 then ASA-2 is reachable. So how they will sync.&lt;/P&gt;
&lt;P&gt;when enabling cluster both ASA &amp;nbsp;becomes MASTER.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any solution ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:02:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037897#M145884</guid>
      <dc:creator>veevekraj</dc:creator>
      <dc:date>2019-03-12T09:02:37Z</dc:date>
    </item>
    <item>
      <title>Hey veevekraj1,</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037898#M145885</link>
      <description>&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;&lt;A href="https://supportforums.cisco.com/users/veevekraj1" title="View user profile." class="username" lang="" about="/users/veevekraj1" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;Hey veevekraj1, &lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Did you get a solution or work-around for this issue? I am facing a similar dilemma now. Kindly share how you handled this.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="fullname" itemprop="author"&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 16:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037898#M145885</guid>
      <dc:creator>Kunle</dc:creator>
      <dc:date>2017-05-25T16:44:28Z</dc:date>
    </item>
    <item>
      <title>In ASA cluster we need</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037899#M145887</link>
      <description>&lt;BLOCKQUOTE&gt;
&lt;P&gt;In ASA cluster we need minimum 2 link form each ASA for a port channel. Otherwise it will not be a good implementation. If u will use only one link per ASA for CCL link then it will hamper data interface. Like.....when cluster port channel will go down cluster will break and data interface of the context will also go down.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Apart from cluster issue my issue was related to etherchannel. Need to check etherchannel configuration and issue will be resolved.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Fri, 26 May 2017 06:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037899#M145887</guid>
      <dc:creator>veevekraj</dc:creator>
      <dc:date>2017-05-26T06:57:26Z</dc:date>
    </item>
    <item>
      <title>Thanks veevekraj1</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037900#M145888</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks &lt;SPAN class="fullname"&gt;&lt;SPAN rel="sioc:has_creator"&gt;&lt;A href="https://supportforums.cisco.com/users/veevekraj1" title="View user profile." class="username" lang="" about="/users/veevekraj1" typeof="sioc:UserAccount" property="foaf:name" datatype=""&gt;veevekraj1&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 19:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-issue/m-p/3037900#M145888</guid>
      <dc:creator>Kunle</dc:creator>
      <dc:date>2017-05-29T19:52:57Z</dc:date>
    </item>
  </channel>
</rss>

